Skip to content

Commit b40c53e

Browse files
authored
Add permissions to GitHub service account to deploy to dbt (#3864)
Signed-off-by: Doc Ritezel <[email protected]>
1 parent 3ffe254 commit b40c53e

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

iac/cal-itp-data-infra/iam/us/project_iam_member.tf

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -551,11 +551,11 @@ resource "google_project_iam_member" "github-actions-terraform" {
551551

552552
resource "google_project_iam_member" "github-actions-service-account" {
553553
for_each = toset([
554-
"roles/bigquery.dataViewer",
555-
"roles/bigquery.jobUser",
556-
"roles/bigquery.readSessionUser",
554+
"roles/bigquery.filteredDataViewer",
555+
"roles/bigquery.metadataViewer",
557556
"roles/composer.admin",
558-
"roles/storage.admin"
557+
"roles/storage.objectAdmin",
558+
google_project_iam_custom_role.tfer--projects-002F-cal-itp-data-infra-002F-roles-002F-DataAnalyst.id
559559
])
560560
role = each.key
561561
member = "serviceAccount:${google_service_account.github-actions-service-account.email}"

0 commit comments

Comments
 (0)